US2024202824A1PendingUtilityA1
Smart contract security auditing
Assignee: QATAR FOUND EDUCATION SCIENCE & COMMUNITY DEVPriority: Dec 14, 2022Filed: Dec 11, 2023Published: Jun 20, 2024
Est. expiryDec 14, 2042(~16.4 yrs left)· nominal 20-yr term from priority
G06F 21/577G06Q 2220/00H04L 63/1433G06Q 20/4016G06Q 40/04
41
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Smart contract auditing may be provided by: receiving a request to audit a prospective smart contract; executing a smart contracts auditing model; extracting raw data from at least one blockchain using the smart contracts auditing model; analyzing the raw data using at least two security analyzers; aggregating the output of the at least two security analyzers according to an aggregator; and generating a smart contracts security report from the aggregated output for the prospective smart contract, which includes a smart contracts security score.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A smart contracts auditing system, comprising:
a processor, and a memory storing instructions, that when executed by the processor, perform operations, including:
receiving a request to audit a prospective smart contract;
executing a smart contracts auditing model;
extracting raw data from at least one blockchain using the smart contracts auditing model;
analyzing the raw data using at least two security analyzers;
aggregating outputs from the at least two security analyzers according to an aggregator; and
generating a smart contracts security report from the outputs as aggregated for the prospective smart contract, which includes a smart contracts security score.
2 . The system of claim 1 , wherein the raw data extracted from the at least one blockchain include code and state data for at least one other smart contract stored in the at least one blockchain.
3 . The system of claim 1 , wherein the at least two security analyzers analyze the raw data by parsing and classifying the raw data into one or more vulnerability categories.
4 . The system of claim 3 , wherein the smart contracts security report includes a visual breakdown of vulnerabilities from the other smart contract identified according to the one or more vulnerability categories.
5 . The system of claim 3 , wherein the one or more vulnerability categories include:
reentrancy; timestamp dependencies; integer overflow; integer underflow; uncheck call return values; arithmetic issues; and inclusion of parity wallets.
6 . The system of claim 3 , wherein each identified vulnerability is weighted according to a severity for an associated vulnerability category to generate the smart contracts security score.
7 . The system of claim 1 , wherein the prospective smart contract is not yet deployed in the at least one blockchain.
8 . A method, comprising:
receiving a request to audit a prospective smart contract; executing a smart contracts auditing model; extracting raw data from at least one blockchain using the smart contracts auditing model; analyzing the raw data using at least two security analyzers; aggregating outputs from the at least two security analyzers according to an aggregator; and generating a smart contracts security report from the outputs as aggregated for the prospective smart contract, which includes a smart contracts security score.
9 . The method of claim 8 , wherein the raw data extracted from the at least one blockchain include code and state data for at least one other smart contract stored in the at least one blockchain.
10 . The method of claim 8 , wherein the at least two security analyzers analyze the raw data by parsing and classifying the raw data into one or more vulnerability categories.
11 . The method of claim 10 , wherein the smart contracts security report includes a visual breakdown of vulnerabilities in the other smart contract identified according to the one or more vulnerability categories.
12 . The method of claim 10 , wherein the one or more vulnerability categories include:
reentrancy; timestamp dependencies; integer overflow; integer underflow; uncheck call return values; arithmetic issues; and inclusion of parity wallets.
13 . The method of claim 10 , wherein each identified vulnerability is weighted according to a severity for an associated vulnerability category to generate the smart contracts security score.
14 . The method of claim 8 , wherein the prospective smart contract is not yet deployed in the at least one blockchain.
15 . A non-transitory computer readable storage device including instructions that, when executed by a processor, perform operations including:
receiving a request to audit a prospective smart contract; executing a smart contracts auditing model; extracting raw data from at least one blockchain using the smart contracts auditing model; analyzing the raw data using at least two security analyzers; aggregating outputs from the at least two security analyzers according to an aggregator; and generating a smart contracts security report from the outputs as aggregated for the prospective smart contract, which includes a smart contracts security score.
16 . The device of claim 15 , wherein the raw data extracted from the at least one blockchain include code and state data for at least one other smart contract stored in the at least one blockchain.
17 . The device of claim 15 , wherein the at least two security analyzers analyze the raw data by parsing and classifying the raw data into one or more vulnerability categories.
18 . The device of claim 17 , wherein the smart contracts security report includes a visual breakdown of vulnerabilities identified from the other smart contract according to the one or more vulnerability categories.
19 . The device of claim 17 , wherein the one or more vulnerability categories include:
reentrancy; timestamp dependencies; integer overflow; integer underflow; uncheck call return values; arithmetic issues; and inclusion of parity wallets.
20 . The device of claim 17 , wherein each identified vulnerability is weighted according to a severity for an associated vulnerability category to generate the smart contracts security score.Join the waitlist — get patent alerts
Track US2024202824A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.